A Comparative Audit of Privacy Policies from Healthcare Organizations in USA, UK and India

06/20/2023
by   Gunjan Balde, et al.
0

Data privacy in healthcare is of paramount importance (and thus regulated using laws like HIPAA) due to the highly sensitive nature of patient data. To that end, healthcare organizations mention how they collect/process/store/share this data (i.e., data practices) via their privacy policies. Thus there is a need to audit these policies and check compliance with respective laws. This paper addresses this need and presents a large-scale data-driven study to audit privacy policies from healthcare organizations in three countries – USA, UK, and India. We developed a three-stage novel workflow for our audit. First, we collected the privacy policies of thousands of healthcare organizations in these countries and cleaned this privacy policy data using a clustering-based mixed-method technique. We identified data practices regarding users' private medical data (medical history) and site privacy (cookie, logs) in these policies. Second, we adopted a summarization-based technique to uncover exact broad data practices across countries and notice important differences. Finally, we evaluated the cross-country data practices using the lens of legal compliance (with legal expert feedback) and grounded in the theory of Contextual Integrity (CI). Alarmingly, we identified six themes of non-alignment (observed in 21.8% of data practices studied in India) pointed out by our legal experts. Furthermore, there are four potential violations according to case verdicts from Indian Courts as pointed out by our legal experts. We conclude this paper by discussing the utility of our auditing workflow and the implication of our findings for different stakeholders.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/21/2021

Detecting Compliance of Privacy Policies with Data Protection Laws

Privacy Policies are the legal documents that describe the practices tha...
research
01/21/2022

Privacy Policies Across the Ages: Content and Readability of Privacy Policies 1996–2021

It is well-known that most users do not read privacy policies, but almos...
research
10/11/2017

Understanding Organizational Approach towards End User Privacy

End user privacy is a critical concern for all organizations that collec...
research
12/04/2022

A Fine-grained Chinese Software Privacy Policy Dataset for Sequence Labeling and Regulation Compliant Identification

Privacy protection raises great attention on both legal levels and user ...
research
09/28/2021

Fighting the Fog: Evaluating the Clarity of Privacy Disclosures in the Age of CCPA

Vagueness and ambiguity in privacy policies threaten the ability of cons...
research
02/27/2023

Priorities for more effective tech regulation

Ample research has demonstrated that compliance with data protection pri...
research
07/27/2018

An experiment in distributed Internet address management using blockchains

The current system to manage the global pool of IP addresses is centrali...

Please sign up or login with your details

Forgot password? Click here to reset